numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution
Published Jan 16, 2019
9.3
CRITICALCVSS 4.0
EPSS 17.53%
Description
An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.
Affected products
No data.
Configuration 2
- 30
No data.
Red Hat Enterprise Linux 8
numpy-1:1.14.3-9.el8
Fixed · RHSA-2019:3704
Red Hat Enterprise Linux 8
python27:2.7-8010020190903182548.51c94b97
Fixed · RHSA-2019:3335
Red Hat Ceph Storage 4
numpy
Affected
Red Hat Enterprise Linux 6
numpy
Will not fix
Red Hat Enterprise Linux 7
numpy
Will not fix
Red Hat OpenStack Platform 13 (Queens)
numpy
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
numpy
Will not fix
Red Hat Software Collections
python27-numpy
Will not fix
Red Hat Software Collections
rh-python35-numpy
Will not fix
Red Hat Software Collections
rh-python36-numpy
Will not fix
Red Hat Virtualization 4
rhvm-appliance
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | numpy-1:1.14.3-9.el8 | Fixed | RHSA-2019:3704 |
| Red Hat Enterprise Linux 8 | python27:2.7-8010020190903182548.51c94b97 | Fixed | RHSA-2019:3335 |
| Red Hat Ceph Storage 4 | numpy | Affected | n/a |
| Red Hat Enterprise Linux 6 | numpy | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | numpy | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | numpy | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | numpy | Will not fix | n/a |
| Red Hat Software Collections | python27-numpy | Will not fix | n/a |
| Red Hat Software Collections | rh-python35-numpy | Will not fix | n/a |
| Red Hat Software Collections | rh-python36-numpy | Will not fix | n/a |
| Red Hat Virtualization 4 | rhvm-appliance | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Virtualization Management Appliance includes the vulnerable version of numpy, however it is not used and this vulnerability is not exposed. Red Hat OpenStack Platform includes a vulnerable version of numpy, however it is not used in a vulnerable manner.
References (21)
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00091.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00092.html vendor-advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00015.html vendor-advisory
- http://www.securityfocus.com/bid/106670 vdb-entryThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3335 vendor-advisory
- https://access.redhat.com/errata/RHSA-2019:3704 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2019-6446 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1667950 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1122208 ExploitIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0098 Advisory
- https://github.com/advisories/GHSA-9fq2-x9r6-wfmf Advisory
- https://github.com/numpy/numpy/commit/89b688732b37616c9d26623f81aaee1703c30ffb
- https://github.com/numpy/numpy/issues/12759 ExploitIssue TrackingThird Party Advisory
- https://github.com/numpy/numpy/pull/12889
- https://github.com/numpy/numpy/pull/13359
- https://github.com/pypa/advisory-database/tree/main/vulns/numpy/PYSEC-2019-108.yaml
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7ZZAYIQNUUYXGMKHSPEEXS4TRYFOUYE4
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZZAYIQNUUYXGMKHSPEEXS4TRYFOUYE4 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-6446
- https://web.archive.org/web/20210124234613/https://www.securityfocus.com/bid/106670
- https://www.cve.org/CVERecord?id=CVE-2019-6446
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub